Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8960979
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 15, 20262026-06-15T15:46:52+00:00 2026-06-15T15:46:52+00:00

I inherited an existing .net web application. It is an external website that is

  • 0

I inherited an existing .net web application. It is an external website that is used by external users and internal users. To login/authenticate internal users, it uses LDAP authentication. External users goes to a different DB.

My IT department wants to change the way internal users login. They do not want to allow an external server to be able to access the AD using LDAP. Is there a more secure method to access the AD from an external server? Or is that not recommended at all?

Also, is the design of the login flawed? Should internal and external users be logging in the same way? What is considered best practice for logging in users?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-15T15:46:54+00:00Added an answer on June 15, 2026 at 3:46 pm

    You could use ADFS (Active Directory Federation Services) for this.

    This will require you to install an ADFS server inside of your network (so it can contact the AD).

    The ADFS Server contains a web based STS (Security Token Service) to allow web pages to login using an AD account.

    Basicly in a nutshell it will work as following:

    1. Your user navigates to the external Web Application
    2. The Web Application will redirect the user to the ADFS STS server.
    3. ADFS STS Server will verify your credentials (either by using integrated security or a web based login box)
    4. If the ADFS STS Server is happy abou the credentials it will then redirect the user back to the external Web Application with a login token as extra information. This token contains information about the user (can be configured). It is signed by the ADFS server (to ensure the information is authentic) and can optionally be encrypted.
    5. The external web application extracts the token and tests the signature. If it is all correct the Web Application will grand the permissions that the user should have.

    For information to set this up in an ASP.NET application you could refer to the following url:
    http://blogs.msdn.com/b/alextch/archive/2011/06/27/building-a-test-claims-aware-asp-net-application-and-integrating-it-with-adfs-2-0-security-token-service-sts.aspx

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have inherited an big existing PHP application (website actually) that runs on Apache.
I have inherited an application that uses the ASP.NET membership provider for user management.
I inherited an ASP.NET application that builds pages with massive viewstate values. As I
I've inherited an old Asp.Net website (I've had limited exposure to Asp & Web
I need to implement a dialog for a web application (ASP.NET/C#) where users can
I inherited a shell-script application that is a combination of kshell scripts, awk, and
I inherited a bugzilla-like page that allows users to look at the bug list.
I have inherited a Web Application project (3 files per aspx page), along with
I have a .Net 3.5 app with a web service that inherits from System.ServiceModel.ClientBase<>,
I have an existing asp.net c# application for which I'd like to implement a

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.